arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

用于QKD增强IPsec隧道的基于哨兵的故障转移

Sentinel-Based Failover for QKD-Augmented IPsec Tunnels

Juan Carlos Hernandez-Hernandez, Francesco Vista, Haftay Gebreslasie Abreha, Intidhar Bedhief, Seid Koudia, Symeon Chatzinotas

arXiv 2609.01121首次发表:更新:

发表机构

University of Luxembourg(卢森堡大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文针对QKD增强IPsec隧道的可用性问题,设计实现了基于哨兵协调协议的量子安全密钥建立机制,实验验证其可在QKD基础设施故障时维持隧道可用性,且性能损失较小。

AI 中文摘要

通过混合密钥建立实现量子安全IPsec是可行的,但会带来一个关键操作挑战:当QKD基础设施不可用时,如何维持隧道的可用性。本文提出了一种用于IPsec隧道的量子安全密钥建立机制的设计、实现与实验评估,该机制通过RFC 9370多密钥交换机制结合X25519、ML-KEM和ETSI GS QKD 014密钥,且在QKD密钥交付失败时能优雅降级。我们的开源StrongSwan插件采用基于哨兵的协调协议,从而允许即使QKD分支失败也能完成握手,而非中止,并在下一次重新密钥时恢复QKD份额。在连接到33公里部署光纤上的城域QKD链路的测试台上,我们评估了五种配置,从经典X25519与RSA的基线配置到添加ML-KEM-1024和QKD密钥的混合配置。完整混合认证耗时103毫秒,而基线配置为61毫秒,QKD检索本身仅增加约7毫秒。故障注入实验证实,隧道在KME完全中断时能存活,且受保护的流量不会出现任何中断。

英文摘要

Quantum-safe IPsec through hybrid key establishment is practical, but creates a critical operational challenge: how to maintain tunnel availability when the QKD infrastructure becomes unavailable. In this paper, we present the design, implementation, and experimental evaluation of a quantum-safe key establishment mechanism for an IPsec tunnel that combines X25519, ML-KEM, and ETSI GS QKD 014 keys through the RFC 9370 multiple key exchange mechanism, and that degrades gracefully when the QKD key delivery fails. Our open-source StrongSwan plugin uses a sentinel-based coordination protocol, thereby permitting us to complete the handshake even if the QKD leg fails, instead of aborting, restoring the QKD share at the next rekey. On a testbed connected to a metropolitan QKD link over 33 km of deployed fiber, we evaluated five configurations, from a classical X25519 with RSA baseline to a hybrid one that adds ML-KEM-1024 and a QKD key. The full hybrid authentication costs 103 ms against 61 ms for the baseline, the QKD retrieval itself adds only about 7 ms. Failure injection experiments confirm that the tunnel survives a complete KME outage without any interruption of the protected traffic.

CommentsWork accepted at the 1st International Workshop on Networked Quantum Systems and Applications (NetQSA 2026) within the 34th IEEE International Conference on Network Protocols, Tempe, Arizona, USA, October 05-08, 2026

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑